Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Comments
IoT Security's Coming of Age Is Overdue
Newest First  |  Oldest First  |  Threaded View
Saumitra Das
50%
50%
Saumitra Das,
User Rank: Author
4/26/2019 | 3:12:23 AM
Re: We need to improve, pronto
This is the nature of our industry where the bad guys have TIME as you mention but many are incredibly well funded as well. As you say, they need to find one hole while we have to patch or inspect all points of entry. In my past roles, I have seen targeted attacks where no threat intel would help since the payloads, domains, IPs were all new and custom. So every attack is "unknown" when you see it and so you sandbox and you are minutes to hours behind depending on how evasive the threat is. Having a different technique that can provide a low false positive verdict in near real time can help burdened SOC teams in prioritizing and going after threats before they have spread futher in and is one step we can make towards shifting this TIME imbalance.
Saumitra Das
50%
50%
Saumitra Das,
User Rank: Author
4/26/2019 | 3:07:17 AM
Re: We need to improve, pronto
I think there has been a lot of focus on compliance, auditing and visilibty as it related to security. We have given up on early detection at the point of intrusion and basically assumed breach and focused on hunting for post infection IOCs with NTA and SIEM. This exacerbates the problems for an overloaded SOC team already receiving tons of logs and alerts and struggling to deal with them given the cyber talent shortage. While hunting for threats assuming breach is a good layer to have, equal or more focus should be given to detecting as early as possible so the risk of breach is minimized and we only have to threat hunt for the very few that may be sophisticated enough to still make it through.
REISEN1955
50%
50%
REISEN1955,
User Rank: Ninja
2/15/2019 | 7:05:56 AM
Re: We need to improve, pronto
The bad guys ( all of them ) have nothing but TIME on their hands - they have all day to just THINK about how to bypass any security function and this is an incredible advantage.  WE have to deal with trying to out-think them while dealing with a few thousand corporate rules, regulations, budget and time issues.  We have an 8-12 hour working day standard.  The bad guys have 24 hour days all of the time.  There we have a mega disadvantage in effort and, besides,   I always believe we are forever 5 minutes behind the the bad guys all of the time. 
StephenGiderson
50%
50%
StephenGiderson,
User Rank: Strategist
2/14/2019 | 9:35:31 PM
We need to improve, pronto
As technology evolves, so should security. However, in this rapidly progressing era, that unfortunately isn't the case. As we witness constant development of various technologies, we sadly also experience major lapses in security over various platforms. Consumer data is sacrificed affecting not only individuals but large corporations as well. Major loss of confidence has occurred over the course of just less than a decade and how can we seriously improve?
UdyRegan
50%
50%
UdyRegan,
User Rank: Apprentice
2/14/2019 | 2:01:46 AM
Many entry points..
The more connections you have to an information hub, the more security you're going to need. Every access point is a potential threat, of course. I'm pretty sure that you'll be able to find some good solutions to beef up the security of the data storage points though. That at least is one way to implement a bit of protection.
Saumitra Das
100%
0%
Saumitra Das,
User Rank: Author
2/4/2019 | 2:30:53 PM
Re: Blockchain
Blockchain for IoT is an interesting area for distributed trust between devices and the entities they interact with. However, security itself can be about the IoT device being tampered with in terms of transacting with other entities as well as being compromised itself leading to lateral movement in the enterprise. Additionally, many IoT systems are battery, CPU and network bandwidth constrained which can be challenging for deploying blockchain. Neural network based threat detection can help identify compromise early and has the potential to be a key enabler of this ecosystem.
blodgettcalvin
50%
50%
blodgettcalvin,
User Rank: Apprentice
2/4/2019 | 11:21:15 AM
Blockchain
In fact, there are already many protection technologies. The most popular is the blockchain system. Also, the development of neural networks makes itself felt and there will soon be a new system based on neural systems.


Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
6 Emerging Cyber Threats That Enterprises Face in 2020
This Tech Digest gives an in-depth look at six emerging cyber threats that enterprises could face in 2020. Download your copy today!
Flash Poll
State of Cybersecurity Incident Response
State of Cybersecurity Incident Response
Data breaches and regulations have forced organizations to pay closer attention to the security incident response function. However, security leaders may be overestimating their ability to detect and respond to security incidents. Read this report to find out more.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-5292
PUBLISHED: 2020-03-31
Leantime before versions 2.0.15 and 2.1-beta3 has a SQL Injection vulnerability. The impact is high. Malicious users/attackers can execute arbitrary SQL queries negatively affecting the confidentiality, integrity, and availability of the site. Attackers can exfiltrate data like the users' and admini...
CVE-2020-7009
PUBLISHED: 2020-03-31
Elasticsearch versions from 6.7.0 to 6.8.7 and 7.0.0 to 7.6.1 contain a privilege escalation flaw if an attacker is able to create API keys. An attacker who is able to generate an API key can perform a series of steps that result in an API key being generated with elevated privileges.
CVE-2019-13495
PUBLISHED: 2020-03-31
In firmware version 4.50 of Zyxel XGS2210-52HP, multiple stored cross-site scripting (XSS) issues allows remote authenticated users to inject arbitrary web script via an rpSys.html Name or Location field.
CVE-2020-5291
PUBLISHED: 2020-03-31
Bubblewrap (bwrap) before version 0.4.1, if installed in setuid mode and the kernel supports unprivileged user namespaces, then the `bwrap --userns2` option can be used to make the setuid process keep running as root while being traceable. This can in turn be used to gain root permissions. Note that...
CVE-2019-14905
PUBLISHED: 2020-03-31
A vulnerability was found in Ansible Engine versions 2.9.x before 2.9.3, 2.8.x before 2.8.8, 2.7.x before 2.7.16 and earlier, where in Ansible's nxos_file_copy module can be used to copy files to a flash or bootflash on NXOS devices. Malicious code could craft the filename parameter to perform OS co...